Critical Gitea Vulnerability Enables Private Repository Writes and Actions Workflow Triggers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 Gitea users are urged to update immediately after a critical vulnerability was disclosed that allows public-only repository access tokens to indirectly write to private pull request branches and trigger private Actions workflows. Tracked as CVE-2026-58443, the vulnerability …

Hackers Could Turn AI Training Jobs Into Weapons Against the Power Grid

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 A new research threat called Bit2Watt shows how AI training jobs could be abused to disrupt the power systems that support data centers. Rather than installing malware or breaking into grid controls, an attacker could use legitimate …

The Privilege Paths Attackers See, That You Don’t – A Complete PAM Guide

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Why identity fragmentation is the blind spot behind most breaches—and what a platform approach changes The Identity Problem Hiding in Plain Sight Identity is at the centre of nearly every major breach—yet most organisations still can’t answer one fundamental question: what …

Hackers Turn Telegram Bots Into Secret Backdoor Controllers for Government Systems

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 A newly uncovered cyberespionage campaign has turned Telegram bots into quiet controllers for backdoors planted inside Middle Eastern government networks. The operation relies on familiar Windows components and legitimate-looking files, allowing attackers to establish access without immediately …

Hackers Exploiting Palo Alto’s PAN-OS Vulnerability to Deploy Qilin Ransomware

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Threat actors are actively exploiting a critical authentication bypass flaw in Palo Alto Networks firewalls to breach corporate networks and deploy Qilin ransomware, according to new research from Arctic Wolf Labs. The security firm investigated multiple intrusions throughout June 2026, …

Furtex – Linux Toolkit for Post-Exploitation and Evasion for Security Researchers and Red Teamers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 21, 2026 A new open-source project, Furtex, has emerged as a Linux-focused post-exploitation and evasion research toolkit for authorized security researchers and red-team operators. The project combines raw io_uring system calls, BPF and eBPF tooling, and EDR-evasion research utilities …

Hackers Are Turning Microsoft 365 Calendar Invites Into Secret Malware Command Channels

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 20, 2026 A stealthy new malware strain called HOLLOWGRAPH that hijacks Microsoft 365 calendars to secretly communicate with hackers, disguising malicious commands as ordinary calendar invites. HOLLOWGRAPH is a .NET-compiled malware component that abuses the Microsoft Graph API through …

Windows Bind Link Abuse Lets Attackers Blind EDR and Bypass AMSI, AppLocker, and Sysmon

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

July 20, 2026 Windows defenders are facing a new way for attackers to hide activity after gaining administrator access. The technique abuses Windows bind links, a legitimate feature that redirects one file path to another without changing the original file …

Critical wp2shell RCE Vulnerability – Complete Coverage Including PoC and Active Exploitation Details

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical pre-authentication remote code execution (RCE) vulnerability chain nicknamed “wp2shell” has been disclosed in WordPress Core, putting an estimated 500 million-plus websites at risk of full takeover by completely unauthenticated attackers. The chain combines two separately tracked flaws CVE-2026-63030, …

Paidwork Data Breach Exposes 23 Million Users’ Banking and Personal Data

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A massive data breach has hit Paidwork, a popular gig economy platform, exposing sensitive banking and personal information belonging to more than 23 million users worldwide. The incident, first surfacing in March 2026 when hackers listed the stolen data for …